
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
koa-static
Advanced tools
Koa static file serving middleware, wrapper for koa-send
.
$ npm install koa-static
const Koa = require('koa');
const app = new Koa();
app.use(require('koa-static')(root, opts));
root
root directory string. nothing above this root directory can be servedopts
options object.maxage
Browser cache max-age in milliseconds. defaults to 0hidden
Allow transfer of hidden files. defaults to falseindex
Default file name, defaults to 'index.html'defer
If true, serves after return next()
, allowing any downstream middleware to respond first.gzip
Try to serve the gzipped version of a file automatically when gzip is supported by a client and if the requested file with .gz extension exists. defaults to true.br
Try to serve the brotli version of a file automatically when brotli is supported by a client and if the requested file with .br extension exists (note, that brotli is only accepted over https). defaults to true.extensions
Try to match extensions from passed array to search for file when no extension is sufficed in URL. First found is served. (defaults to false
)const serve = require('koa-static');
const Koa = require('koa');
const app = new Koa();
// $ GET /package.json
app.use(serve('.'));
// $ GET /hello.txt
app.use(serve('test/fixtures'));
// or use absolute paths
app.use(serve(__dirname + '/test/fixtures'));
app.listen(3000);
console.log('listening on port 3000');
koa-static
to a specific pathMIT
The serve-static package is a middleware for Express, another popular Node.js web framework. It serves static files similarly to koa-static but is designed for use with Express. It offers similar functionalities such as serving files from a directory and customizing options like cache control.
The static-server package is a simple, standalone HTTP server for serving static files. Unlike koa-static, it is not a middleware and does not require a web framework like Koa or Express. It is useful for quickly serving static files without setting up a full web server.
The http-server package is a simple, zero-configuration command-line HTTP server. It is used to serve static files and is often used for development and testing purposes. Unlike koa-static, it is not a middleware and does not integrate with web frameworks.
FAQs
Static file serving middleware for koa
The npm package koa-static receives a total of 763,653 weekly downloads. As such, koa-static popularity was classified as popular.
We found that koa-static demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 10 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.